Cops visit school of 'wrong person's child,' mix up victims and suspects in epic data fail
- Reference: 1709296835
- News link: https://www.theregister.co.uk/2024/03/01/west_midlands_police_data_protection/
- Source link:
Britain's data watchdog says the force "incorrectly linked and merged the records" of the individuals that share the same name and date of birth on multiple occasions during 2000, 2021 and 2022.
The unnamed pair were both victims of crime, although one had been a suspect was well, "meaning WMP didn't make a clear distinction between the personal information of victims and suspects of crime, a breach of the Data Protection Act 2018," the ICO said in a statement today.
[1]
The series of unfortunate events led to inaccurate personal data being processed and culminated in a litany of mistakes, including officers going to the wrong address when trying to find a person "regarding serious safeguarding concerns." Officer also "incorrectly" visited the school of a wrong person's child.
[2]
[3]
In another incident, one of the individuals was sent a letter by WMP about the other, revealing they had been there victim of serious assault, and at the time the recipient was aware of the data mix-up mess.
"WMP didn't take steps to rectify the error quickly enough and there was a failure to stop the inaccurate linking of records reoccurring, both breaches of data protection law. " said the ICO.
[4]
The data privacy watchdog found WMP hadn't provided regular data protection training or done enough to make employees aware of their role in reporting inaccurate personal information. The force has since launched Data Quality Policy, and launched the "Think before you link" campaign - so catchy that maybe the cops will even remember it.
WMP compensated one of the individuals and sent a letter to "help them address similar data accuracy issues with other organisations," the reprimand states.
The remedial action taken by the force since the ICO launched its probe means the body decided not to fine the police service.
[5]
David Doodson, civil investigations manager at the ICO, said:
"It is essential that police forces handle personal information with the utmost respect to maintain people's trust and confidence in the police. Sharing the same name and birthday as someone else should not mean your personal information is jeopardised, especially given the sensitive nature of the information held.
"This case highlights the importance of training to ensure officers understand data protection law to avoid mistakes like this occurring again."
[6]Manchester's finest drowning in paperwork as Freedom of Information requests pile up
[7]Northern Ireland cops count human cost of August data breach
[8]Regulator says stranger entered hospital, treated a patient, took a document ... then vanished
[9]Greater Manchester Police ransomware attack another classic demo of supply chain challenges
[10]You're not seeing double – yet another UK copshop is confessing to a data leak
[11]Cumbrian Police accidentally publish all officers' details online
The data protection body gave the force four recommendations, saying it should "maintain relevant records of its processing activities and take steps to improve governance measures, take "appropriate action to distinguish the records of the two individuals and prevent further inaccurate linking and merging of records containing personal data. This should include completing the technical changes needed to unmerge the records on the system in a timely manner." It should also ensure "learnings" from security incidents are shared across the org and remind employees of security policies; and, finally, the ICO said, ensure employees attend mandatory data protection training as well as considering "implementing clear policies, procedures and training that is specific to the use of the system."
The force told The Reg : "We acknowledge and accept the reprimand and thank the ICO for their recommendations. We have already fully completed the three recommendations with the fourth being an ongoing responsibility that we take seriously and are investing in.
"We have already apologised to the individuals affected and taken action to minimise the likelihood of this or anything similar happening again."
It added that it handles "millions of records each day" and said "thankfully these data errors are incredibly infrequent." ®
Get our [12]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZeIJuEHegN1th4caYXYPvwAAAUo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeIJuEHegN1th4caYXYPvwAAAUo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeIJuEHegN1th4caYXYPvwAAAUo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZeIJuEHegN1th4caYXYPvwAAAUo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZeIJuEHegN1th4caYXYPvwAAAUo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2023/12/20/greater_manchester_police_foi/
[7] https://www.theregister.com/2023/12/12/psni_data_breach_forces_officers/
[8] https://www.theregister.com/2023/12/01/nhs_health_board_ticked_off/
[9] https://www.theregister.com/2023/09/15/greater_manchester_police_breach_demonstrates/
[10] https://www.theregister.com/2023/08/15/norfolk_and_suffolk_police_data_breach/
[11] https://www.theregister.com/2023/08/14/cumbrian_police_accidentally_published_officer_details_online/
[12] https://whitepapers.theregister.com/
Ah good. It's not just me enjoying the irony of so many mistakes, in an article about cops making many mistakes.
Wrapped?
Page tab title now corrected from "Police wrapped" to "Police rapped".
Personally, I would support the ICO having the power to encase in clingfilm as a punishment.
Plus ça change
Back in the day (24 years ago? really? blink and you miss it), in another life, I found it extremely odd that the local force system (and probably the PNC on which it was modelled) was set up assuming that no two "customers" would have the same name and DoB (That's what ID cards are for lol)... there were provisons for the occurrance, of course, but they weren't immediately obvious. I did ask a question but got a shrug from the Inspector.
So, in this case, once the mess started I doubt there was much the force could do to sort it out becasue officers/staff would be querying the data, getting whichever "customer" was first, and, assuming that the computer was giving them the right "customer", modifying the record accordingly and consequently screwing up the data leading to much unpleasantness all round.
To compound the issue, IIRC the UI didn't allow an officer to correct the mistake, even if they had noticed the snfu, (24x7) so the data manager (0900-1700 Monday - Friday if you were lucky) would have to have knowledge of the records concerned and not make a mistake when unpicking the mess.
Re: Plus ça change
In same early 2000s era I was building a data deduplication system for banks to deal with OFAC and all the terrorists under the bed hysteria after 9/11.
Demonstrating it to the MET we were shown their in-house system that had a bunch of DB scripts to automatically match Alistair=Alisdair=Al=Ali
Great for matching 60s E London gangsters, not so great against Al-Qaeda, or Alistair-Qaeda to the boys in blue.
Just in case...
...anyone recognises a possible repeat of this anywhere in the UK's labyrinthine public sector IT estate
https://ccea.org.uk/regulation/guidance/unique-learner-number
Ccea blocks me, why?
When I try to see anything on ccea.org.uk I am blocked. I live in Canada. What is ccea hiding?
Re: Ccea blocks me, why?
Oh, they don't like US either (just checked using my sdf.org shell account and links)!
I have absolutely no idea why they do that. Try
https://www.gov.uk/guidance/how-to-access-your-personal-learning-record
The actual UK government Web page for students about the personal learning record that uses the ULN as the key.
"thankfully these data errors are incredibly infrequent"
Yes. I'm sure that is quite reassuring for the people who do become victims of such errors.
They undoubtedly console themselves by thinking how absolutely infrequent such errors are.
Especially when the error is brought to light, and police forces continue to confuse them for months afterwards.
Similar mistakes not limited to public sector
I went to Boots opticians for an eye test, having not used them for a number of years. Surprisingly they found my record on their computer system from only a couple of years earlier. I was somewhat baffled, but the optician proceeded to test my sight based on "my" previous visit. I couldn't even read the first big letter at the top of the chart. I said there must be a mistake somewhere. He checked my address on their system and it was my address, but from somewhere I'd lived twenty years earlier, my ancient phone number and my date of birth but not the same medications, medical history or eye test results. The optician was convinced there must be someone living there now with the same name and DOB as me, which I thought highly unlikely. It seemed blindingly obvious to me that Boots had somehow merged two patient records into one. Not used Boots opticians since, wasn't impressed with their service either.
Re: Similar mistakes not limited to public sector
When I lived in the UK I regularly got letters about somebody's fertility treatment - who had the same Initial and Surname as me but an entirety opposite set of baby making bits.
I was slightly tempted to turn up to one of the appointments
Re: Similar mistakes not limited to public sector
Boots, when I last used them a long tme ago, seemed to build their business using locums and short term staff.
Re: Similar mistakes not limited to public sector
I got a couple of Boots opticians letters for someone else sent to me a few years ago. I've never been to Boots opticians, and I know all the owners of my house going back to 1983 and it wasn't any of them, so maybe Boots are just a bit rubbish.
.
Not the first time...
...that WMP have performed this particular trick. My dad was arrested once, on Easter weekend in or around 2005.
The cops had nabbed someone in Staines for something or other, took the guy's name, DoB and address and let him go. Come his day in court, he didn't show up. The address he'd given turned out to be false. So they looked up the name and DoB in the Dept of Work & Pensions database (which they shouldn't have done, and ignoring that he'd lied once already) and came up with my dad. Then issued a warrant for his arrest. Because they'd knocked on my dad's door on Raster weekend, they were going to hold him until the next working day (tues) because "he'd already skipped bail once".
Eventually, the duty sargeant released him on common sense grounds, but advised he don't leave town for a few days.
Ironically, the police in Staines had a photo of their actual suspect, but never thought to send it with the warrant.
An absolute shit-show, start to finish
Re: Not the first time...
I'm assuming Raster weekend wasn't a politically incorrect 80s term for the Notting Hill carnival?
Re: Not the first time...
No, it's a little-celebrated public holiday in the UK in recognition of some poor tit with poor mobile phone typing skills.
Co-incidentally, it takes place over Easter.
Re: Not the first time...
On Sunday 25th February Foden's Band became Northern Brass Band Champions.
Just the day that Facebook decided that "Fodens" should be autocorrected to "Fuck".
Fixed the next day!
Clearly they need access to more personal data, location, habits and behavior patterns to prevent cases like this going forward. Maybe Meta or Alphabet can offer them some nice data sets at a friendship rate that police can then use to accurately identify individuals, or whatever else they happen to consider doing with this information.
Or put a microchip in each person's neck.
That's why we need ID cards - to protect the children
Conflicting aims?
it should "maintain relevant records of its processing activities and take steps to improve governance measures"
Interestingly. these recommendations and the relevant provisions of the Data Protection and Digital Information Bill are at odds, in that, by paring down the record keeping requirement, the Bill aims to minimise the "red tape" associated with detailed record keeping inherited from the GDPR.
Oliver Dowden has the solution - NOT
See: https://www.theregister.com/2024/03/01/uk_gov_generative_ai_plan/
"The UK government will trial large language models to help ministers analyze and draft documents as part of a push to overhaul public services using AI.
In a speech on Thursday, deputy prime minister Oliver Dowden called the technology a potential "silver bullet" to reduce the burden of routine admin tasks and make civil servants more productive.
...
More worryingly, perhaps, is Dowden’s idea of crime-prevention algorithms that could "direct police to where they are most needed" and "spot patterns of criminality to discover culprits quicker than ever.""
God help us all.
Re: Oliver Dowden has the solution - NOT
I would suggest they start with Westminster and the House of Commons.
Re: Oliver Dowden has the solution - NOT
> In a speech on Thursday, deputy prime minister Oliver Dowden called the technology a potential "silver bullet" to reduce the burden of routine admin tasks and make civil servants more productive.
I'm going to put this as politely as I can: what a fucking idiot.
Thats ok then
"thankfully these data errors are incredibly infrequent."
Unless your the one getting your liberty infringed by the state who make it incredibly hard to rectify a fault in their data processing especially when they deliberately hide the data they hold on you from you.
Re: Thats ok then
Another data catastrophe that occurs now and then all over the world is if someone is accidentally or maliciously declared dead and the automatic data updates that follow... closure of bank accounts, cancellation of pension, benefits, credit rating, driver's licence, passport etc. Most organisations lack facilities or procedures to make someone "undead" causing considerable suffering to those affected while the bureaucrats just keep repeating "the computer says No".
There are, in this year of our Lord 2024, IT systems keyed simply on first initial and last name. I know this because my wife happens to have the same first initial I do, and we've both gotten numerous official phone calls and letters meant for each other.
I've been summoned to go for flu / covid jabs or random doctor's appointments only to find the appointments were for my wife, the surgery putting my phone number onto her record. To reinforce the confusion, text messages never state who they are intended for.
> The unnamed pair were both victims of crime, although one had been a suspect was well
I'm glad to hear about their good state of health!